Parser
Current version v0.4.0
Last updated
Was this helpful?
Current version v0.4.0
Last updated
Was this helpful?
The Parser gives structure to and divides a JSON, Key Value, CSV, Delimited Values or Fixed Length file into separate fields.
In order to configure this action, you must first link it to a Listener. Go to Building a Pipeline to learn how to link.
These are the input and output ports of this Action:
Find Parser in the Actions tab (under the Transformation group) and drag it onto the canvas.
To open the configuration, click the Action in the canvas and select Configuration.
Enter the required parameters:
Field to parse*
First, choose the field to parse from the Listener by typing it in the search bar or selecting it from the list.
You can also use the arrow keys on your keyboard to navigate up and down the list.
Input*
This is where you specify how to read the incoming data:
real_data - this is the data taken directly from the linked Listener.
paste - there may be times that you will receive a JSON with updated data for the Listener. If this is the case, you can paste it here.
In the Events drop-down, you can write how many events to show in this window.
Now you have specified where to source the data from, you need to determine how to process the events.
Parser*
There are two ways to parse your data:
auto - automatically parses all key-value fields.
manual - manually split fields and rename them.
Here you can view the fields as a list, or as code. Each data type has a color. Learn more here.
The language and grammar used to parse is PCL (Parser Configuration Language). We have provided an extensive run-down of each command in this article.
Now we have decided which field, from where, and how to parse, we need to specify the interpretation of the output to the next action.
Output*
Here you can see the raw message that has been generated.
Below, each individual field is color-coded according to the legend and separated into its type and name.
Here you can change the data type and edit the field name.
For fields containing subfields (field.subfield
), changing the field name will change all of the prefixes.
Click Save to complete the process.
Learn how to use the Parser with this example.
We have opened the configuration of the Parser to our Pipeline, which is receiving data from the linked Listener.
First we must select the field to parse from the Listener to separate into more specific data. This is the field containing the raw data.
In the Input field, select Real data if you feel comfortable with how the Parser works.
Select Paste and paste this log to follow along with us for the various examples of log sources.
A CSV file using "," as a separator
Log to paste
Select Auto to automatically parser this data into separate fields.
The parser will automatically parse the log, having recognized the separator. The default values will be fieldName1,2,3 etc.
Now we have decided which field, from where, and how to parse, we need to specify how it is output to the next action. In the output field, we can change the names of each field.
TIMESTAMP
HOSTNAME
EVENT TYPE
PROCESS NAME
PROCESS ID
USERNAME
IP ADDRESS
HASH
THREAT SCORE
Click Save.